Canto <= 3.1.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Setting Modification
medium
The Canto plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 3.1.1. This is due to the absence of any capability check or nonce verification in the updateOptions() function, which is exposed via two AJAX hooks: wp_ajax_updateOptions (class-canto.php line 231) and wp_ajax_fbc_upd...
- CVSS:
- 4.3
- Affected:
- up to 3.1.1
- Fixed in:
- 3.1.2
- Disclosed:
- Apr 16, 2026
CVE-2026-6441 on NVD →
Canto <= 3.1.1 - Missing Authorization to Unauthenticated File Upload
medium
The Canto plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.1.1 via the `/wp-content/plugins/canto/includes/lib/copy-media.php` file. This is due to the file being directly accessible without any authentication, authorization, or nonce checks, and the `fbc_flight_domain...
- CVSS:
- 5.3
- Affected:
- up to 3.1.1
- Fixed in:
- 3.1.2
- Disclosed:
- Mar 20, 2026
CVE-2026-3335 on NVD →
Canto <= 3.0.8 - Unauthenticated Remote File Inclusion
critical
The Canto plugin for WordPress is vulnerable to Remote File Inclusion in all versions up to, and including, 3.0.8 via the abspath parameter. This makes it possible for unauthenticated attackers to include remote files on the server, resulting in code execution. This required allow_url_include to be enabled on the targe...
- CVSS:
- 9.8
- Affected:
- up to 3.0.8
- Fixed in:
- 3.0.9
- Disclosed:
- Jun 13, 2024
CVE-2024-4936 on NVD →
Canto <= 3.0.6 - Remote File Inclusion to Code Execution
critical
The Canto plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.0.6 via the 'abspath' parameter. This is due to the use of the include_once statement on the parameter allowing remote file inclusion. This makes it possible for unauthenticated attackers to execute code on the...
- CVSS:
- 9.8
- Affected:
- up to 3.0.6
- Fixed in:
- 3.0.7
- Disclosed:
- Feb 12, 2024
CVE-2024-25096 on NVD →
Canto <= 3.0.4 - Unauthenticated Remote File Inclusion
critical
The Canto plugin for WordPress is vulnerable to Remote File Inclusion in versions up to, and including, 3.0.4 via the 'wp_abspath' parameter. This allows unauthenticated attackers to include and execute arbitrary remote code on the server, provided that allow_url_include is enabled. Local File Inclusion is also possibl...
- CVSS:
- 9.8
- Affected:
- up to 3.0.4
- Fixed in:
- 3.0.5
- Disclosed:
- Aug 9, 2023
CVE-2023-3452 on NVD →
Canto <= 1.9.0 - Blind Server-Side Request Forgery via detail.php
high
The Canto plugin 1.9.0 for WordPress contains a blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal and external server via /includes/lib/detail.php?subdomain=SSRF.
- CVSS:
- 8.3
- Affected:
- up to 1.9.0
- Fixed in:
- 2.0.1
- Disclosed:
- Dec 4, 2020
CVE-2020-28976 on NVD →
Canto <= 1.9.0 - Blind Server-Side Request Forgery via download.php
high
The Canto plugin 2.1.1 for WordPress allows includes/lib/download.php?subdomain= SSRF.
- CVSS:
- 8.3
- Affected:
- up to 1.9.0
- Fixed in:
- 2.0.1
- Disclosed:
- Nov 30, 2020
CVE-2020-24063 on NVD →
Canto <= 1.9.0 - Blind Server-Side Request Forgery via get.php
high
The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal and external server via /includes/lib/get.php?subdomain=SSRF.
- CVSS:
- 8.3
- Affected:
- up to 1.9.0
- Fixed in:
- 2.0.1
- Disclosed:
- Mar 12, 2020
CVE-2020-28977 on NVD →
Canto <= 1.9.0 - Blind Server-Side Request Forgery via tree.php
high
The Canto plugin 1.9.0 for WordPress contains blind SSRF vulnerability. It allows an unauthenticated attacker to make a request to any internal and external server via /includes/lib/tree.php?subdomain=SSRF.
- CVSS:
- 8.3
- Affected:
- up to 2.0.1
- Fixed in:
- 2.0.1
- Disclosed:
- Mar 12, 2020
CVE-2020-28978 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database